Catan and Mouse
Reported exploitedMicrosoft 365SimpleHelp RMMOur summary
Cisco Talos highlights ARToken, a phishing-as-a-service operator panel for Microsoft 365 focused on device code phishing, Primary Refresh Token (PRT) persistence, email access/BEC operations, and SharePoint exfiltration—capabilities exposed through 80+ API endpoints. Separately, Talos notes that a recently reported authentication bypass in SimpleHelp remote monitoring and management (RMM), tracked as CVE-2026-48558, has been exploited in the wild to obtain a fully authenticated technician session for malware delivery. These findings matter because they indicate both increasing maturity in credential/theft-driven phishing tooling and active exploitation of authentication weaknesses.
Cisco Talos publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.